Remount Clients
After TLS is enabled on the Hammerspace cluster, each NFS client must be fully unmounted and remounted with TLS mount options. A standard mount -o remount is not sufficient — switching from plaintext NFS to TLS requires a complete unmount and remount due to the fundamental change in the network transport layer.
Before remounting, confirm that certificate trust is configured in both directions: the client must trust the Hammerspace cluster’s CA certificate, and Hammerspace must trust the client’s certificate. See Reference: Certificate Trust Model. A client that mounts without both sides trusting each other fails the TLS handshake.
This section includes the following subsections: